2 ms·
> maybe this medium can also be compromised. Indeed it can. Bunnie & xobs recently showed how to get code running on the controller chips of SD cards [1]. With
by rainforest 12y ago
> maybe this medium can also be compromised.
Indeed it can. Bunnie & xobs recently showed how to get code running on the controller chips of SD cards [1]. With your own implementation you could have the card present alternative files (clean vs infected) to different machines based on read patterns [2] or just a mount count. Without an exploit for the kernel, you'd still need the user to click on one the files, however.
That's not to say your suggestion isn't safer; SD cards don't present a threat to HID attacks (where a USB stick pretends to be a keyboard and is trusted to send inputs), but as with anything, it's not totally safe.
[1] : http://www.bunniestudios.com/blog/?p=3554 http://www.bunniestudios.com/blog/?p=3554
[2] : http://events.ccc.de/congress/2012/Fahrplan/events/5327.en.html http://events.ccc.de/congress/2012/Fahrplan/events/5327.en.h...